Version 0.7.3 · latest release

Confidential AI, Pay Privately, Publish without Permission

Research, build, collaborate, pay and monitor — from anywhere.

Private Provider is a phone-first AI workspace for Android (ARM64). It runs a bundled local runtime with routstrd and the Pi coding agent, pays for inference with a built-in Cashu wallet, and publishes projects through ngit with an external Amber signer.

Signed with certificate 2b356f863d6d752ca7767c68251fea91ab85a2f4ca33366f973bcb37c59bacfa. Please read the known limitations before installing.

What's new in 0.7.3

What's new in 0.7.2

What's new in 0.7.1

What's new in 0.7.0

Why it's different

Confidential AI

Choose a tinfoil-* model and your prompt is encrypted to the attested enclave. The app verifies the hardware measurement and shows the TEE evidence per prompt. Non-attested models are clearly labelled “not private” and need your explicit approval.

Pay privately

Top up a Cashu wallet and pay per query. No accounts, no email, no subscriptions, no credit cards, no KYC. No telemetry, no analytics, no tracking identifiers. You pay only for what you use.

Publish without permission

Every project directory is a full git repository. Publish it to Nostr with built-in ngit — open issues, comment, send pull requests, cut releases — all in the app. Signing goes through Amber (NIP-46), and your npub stays pseudonymous. No platform gatekeeper.

What's included

Chat

Multi-turn chats. tinfoil-* models are verified by hardware attestation and sent encrypted to the attested enclave. Choosing a non-attested model requires an explicit “Not private” approval. Save any exchange as an artifact file in your workspace.

Pi Agent

A coding agent that works in the app's /workspace. It can build Android APKs on the phone with an optional, separately downloaded build toolchain. Pi never receives your Nostr signer.

Files

A project workspace with ngit publishing, releases, pull requests and issues. Publishing is performed by the app and signed through Amber (NIP-46). Amber is optional unless you publish.

Wallet

A Cashu wallet with Lightning top-up and Cashu send. A recovery-phrase backup is required before the wallet is used.

Monitor

Usage, providers, logs, attestation evidence, a privacy statement and data-clearing controls.

A full Pi Agent and on-device APK builds — no laptop required.

Clone any ngit repo, open pull requests and issues, comment, and collaborate over Nostr — all in the app.

Get the app

Version 0.7.3 (274), for Android 8.0+ (API 26+) on an ARM64 device.

Requirements

Download

  1. Preferred: open the release page, find 0.7.3, and tap the APK asset. It downloads from Blossom and Android offers to install it.
  2. Direct download from Blossom (same file, byte-identical):

Verify what you install

The APK is content-addressed, so the URL itself is the SHA-256 of the file.

To check on a computer, download the APK and compare its hash: sha256sum private-provider-0.7.3-274-product.apk. Future updates will be signed with the same certificate.

Install on the phone

  1. Download the APK (either way above).
  2. Android will ask to allow that browser or file manager to install unknown apps — allow it only for the app you're using.
  3. Tap Install, then open Private Provider.
  4. First launch needs ~2 GB free; onboarding installs the local runtime in the background.

About the attestation

Attested tinfoil-* inference is the core of the app. The Monitor tab shows the trusted-execution-environment (TEE) evidence and a verified Attested status — the hardware measurement matches the signed build.

Why it matters: your prompt is encrypted on your device and can only be decrypted inside the secure enclave. A trusted execution environment (TEE) is a sealed part of the processor that runs code in isolation from the rest of the phone, and it can prove cryptographically which code is running. That proof is the attestation — the app shows it, so you can check the claim instead of trusting it.

Not every model is private. Models that are not attested are labelled “not private” and require your explicit acknowledgement before use. The app does not pretend otherwise.

Status and limitations

Version 0.7.3 is the latest public release. It has not been independently audited. These limitations are real — please read them:

This site describes what the app does today, not a promise of what it will do.

Learn more

The application source is free software under the GNU General Public License, version 3 or later. It is distributed without warranty. Bundled native components keep their own licenses.